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- Extensions of time may be available under the provisions of 37 CFR 1 .136(a). In no event, however, may a reply be timely filed 
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Any reply received by the Office later than three months after the mailing date of this communication, even if timely filed, may reduce any 
earned patent term adjustment. See 37 CFR 1 .704(b). 

Status 

1 )KI Responsive to communication(s) filed on 24 January 2008 . 
2a )□ This action is FINAL. 2b)^ This action is non-final. 

3) D Since this application is in condition for allowance except for formal matters, prosecution as to the merits is 

closed in accordance with the practice under Ex parte Quayle, 1935 CD. 11, 453 O.G. 213. 

Disposition of Claims 

4) |EI Claim(s) 1,5,7,8,12-18,20,23,25,27-29,31, 34-36. 39.42 and 43 is/are pending in the application. 

4a) Of the above claim(s) is/are withdrawn from consideration. 

5) D Claim(s) is/are allowed. 

6) EI Claim(s) 1. 5. 7-8. 12-18. 20. 23. 25. 27-29. 31. 34-36. 39 and 42-43 is/are rejected. 

7) 0 Claim(s) is/are objected to. 

8) D Claim(s) are subject to restriction and/or election requirement. 

Application Papers 

9) Q The specification is objected to by the Examiner. 

10) D The drawing(s) filed on is/are: a)D accepted or b)D objected to by the Examiner. 

Applicant may not request that any objection to the drawing(s) be held in abeyance. See 37 CFR 1.85(a). 
Replacement drawing sheet(s) including the correction is required if the drawing(s) is objected to. See 37 CFR 1.121(d). 
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application from the International Bureau (PCT Rule 17.2(a)). 
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DETAILED ACTION 

Continued Examination Under 37 CFR 1.114 

A request for continued examination under 37 CFR 1.114, including the fee set forth in 
37 CFR 1 .1 7(e), was filed in this application after final rejection. Since this application is 
eligible for continued examination under 37 CFR 1 .1 14, and the fee set forth in 37 CFR 
1 .17(e) has been timely paid, the finality of the previous Office action has been 
withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 1/24/2008 has 
been entered. 

Response to Arguments 

Applicant's arguments filed 1/24/2008 have been fully considered but they are not 
persuasive. The Applicant makes one argument with regard to the rejection. The 
Examiner will rebut that argument here. 

The Applicant argues that Dessiatnikov fails to disclose the combining a system 
identifier of server with a key phrase for encryption. 

Dessiatnikov discloses the machine-specific encryption key and further discloses 
the additional secret value to be used for encryption see § Encrypting data Par 4. 

The text of those sections of Title 35, U.S. Code not included in this action can be found 
in a prior Office action. 
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Claim Rejections - 35 USC § 102 

Claims 1, 5, 7-8, 12-18, 20, 23, 25, 27-29, 31, 34-36, 39 and 42-43 are rejected under 
35 U.S.C. 102(a) as being anticipated by NPL1 to Dessiatnikov. 

Regarding Claim 1, 36, 39, Dessiatnikov discloses the requesting database connection 
information web server to a database see § Introduction Par. 1 ; accessing a key phrase 
from a file system of the web application server see § Encrypting data Par. 3; combining 
the system identifier and the key phrase to encrypt data see § Encrypting data Par 4; 
obtaining a name/value string from secure storage file in a global directory via find 
operation see § Storage of connection strings; parsing the name/value string into a 
name string and a value string see § Connection String Properties; decrypting the value 
string with effective encryption key to obtain the database connection information see § 
Encrypting data Par 4. 

Regarding Claim 27, Dessiatnikov discloses the accessing key phrase from a central 
directory of a distributed system see § Configuration files Par. 5 (" The ASP.NET..."). 

Regarding Claim 5, 42, Dessiatnikov discloses the prompting for input to the application 
server see § SQL Authentication vs. Windows Authentication Par. 2 & Par. 3. 



Dessiatnikov, Dmitry. "Securing SQL Connection String" SANS Institute 2004 8 Jan 2004. 
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Regarding Claim 7, 25, 34, 43, Dessiatnikov discloses the password and address of 
database see § Connection String Properties - Table & § SQL Authentication vs. 
Windows Authentication Par. 2. 

Regarding Claim 8, 35, Dessiatnikov discloses the Uniform Resource Locator see § 
COM+ catalog. 

Regarding Claim 24, Dessiatnikov discloses the user and machine specific key to be 
used see § Encrypting data Par. 4. 

Regarding Claim 12, 29, Dessiatnikov discloses the triple DES being used for 
encrypting of connection information see § Encrypting data Par. 3. 

Regarding Claim 13, Dessiatnikov discloses the java string see §lntroduction Par. 2. 

Regarding Claim 14-15, Dessiatnikov discloses the automatically requesting a 
connection to a database and initialization of server see § Introduction Par. 1 & § SQL 
Authentication vs. Windows Authentication Par. 1 . 

Regarding Claim 16-17, 23, Dessiatnikov discloses the server and J2EE standard see § 
Additional measures Par 5 & § Encrypting data Par. 5. 
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Regarding Claim 18, Dessiatnikov discloses the web application server to access key 
phrase from a file system of the application server to connect with a database ,wherein 
the web server includes a system identifier to identify the application server and the key 
phrase is to be combined with the system identifier see § Introduction Par. 1 & § SQL 
Authentication vs. Windows Authentication Par. 1 & § Encrypting data Par 4; central 
repository to store name/value string and to provide the value string to server upon 
receiving key phrase see § Storage of connection strings; a parser to parse the name 
/value string see § Connection String Properties ; database to provide requested data 
to server see § Configuration files Par 3. 

Regarding Claim 20, Dessiatnikov discloses the SQL database see § Abstract. 

Regarding Claim 28, Dessiatnikov discloses the encrypting of data see § Encrypting 
data. 

Regarding Claim 31 , Dessiatnikov discloses the network interface to connect to node 
see § SQL Authentication vs. Windows Authentication; the requesting connection 
information server to another node see § Introduction Par. 1 ; accessing a key phrase to 
decrypt the requested connection information to request connection information see § 
Encrypting data Par. 3; obtaining the requested connection information from secure 
storage file see § Storage of connection strings. 

Claim Rejections - 35 USC § 103 
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Claim 30 is rejected under 35 U.S.C. 103(a) as being unpatentable over NPL to 
Dessiatnikov in view of US Patent 2003/0105977 to Brabson et al. (hereinafter Brabson). 

Regarding Claim 30, Dessiatnikov does not disclose the directory transitioning from 
unencrypted to storing encrypted data. However, Brabson disclose the directory 
transitioning from unencrypted to storing encrypted data see Fig. 10 item 1025 & 1030. 
It would be obvious to one having ordinary skill in the art at the time of the invention to 
include the directory transitioning from unencrypted to storing encrypted data in the 
invention of Dessiatnikov in order to use readily available resource as taught in Brabson 
see Fig. 10 item 1030 & Par. 0009. 

Conclusion 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Venkat Perungavoor whose telephone number is 
(571)272-7213. The examiner can normally be reached on 8:30-5:00. If attempts to 
reach the examiner by telephone are unsuccessful, the examiner's supervisor, Gilberto 
Barron can be reached on 571-272-3799. The fax phone number for the organization 
where this application or proceeding is assigned is 571-273-8300. 
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Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published 
applications may be obtained from either Private PAIR or Public PAIR. Status 
information for unpublished applications is available through Private PAIR only. For 
more information about the PAIR system, see http://pair-direct.uspto.gov. Should you 
have questions on access to the Private PAIR system, contact the Electronic Business 
Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO 
Customer Service Representative or access to the automated information system, call 
800-786-9199 (IN USA OR CANADA) or 571-272-1000. 

/V. P.I 

Examiner, Art Unit 2132 



/Benjamin E Lanier/ 

Primary Examiner, Art Unit 2132 



